# Logstash filter plugin patterns-core

**URL:** <https://discuss.elastic.co/t/logstash-filter-plugin-patterns-core/23900>\
**Category:** Logstash\
**Created:** [June 18, 2015, 10:38am UTC](https://discuss.elastic.co/t/logstash-filter-plugin-patterns-core/23900 "2015-06-18T10:38:05Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Penny\_Lee](https://avatars.discourse-cdn.com/v4/letter/p/df788c/32.png) [@Penny\_Lee](https://discuss.elastic.co/u/Penny_Lee)\
**Post date:** [June 18, 2015, 10:38am UTC](https://discuss.elastic.co/t/logstash-filter-plugin-patterns-core/23900/1 "2015-06-18T10:38:05Z")

</div>

Hi 😁

I installed the `logstash-plugins/logstash-patterns-core` to the `/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-0.1.10/`  
The pattern I tested it work on the [http://grokconstructor.appspot.com/do/constructionstep](http://grokconstructor.appspot.com/do/constructionstep) and [http://grokdebug.herokuapp.com/](http://grokdebug.herokuapp.com/) .  
I would like to ask why I can't parse the log using logstash filter plugin patterns-core.  
Here is my input, filter and output.

Original Log:

```
Jun 18 14:50:35 0.0.0.0/0.0.0.0 pfsp: anomaly ICMP_Misuse id 123 status ongoing severity 5 classification high impact "13.90 Mbps/18.19 Kpps" src 0.0.0.0/0 All dst 0.0.0.0/0 abc start 2015-06-17 07:10:07 +0000 duration 179 percent 181.870000 rate 10000 rateUnit pps protocol icmp flags nil url https://abc/page?id=alert_view&alert_id=123, (managed object "NXG_INFRA"), (parent managed object "nil")

input {
          lumberjack {
            port => 5000
            type => "logs"
            ssl_certificate => "/etc/pki/tls/certs/logstash-forwarder.crt"
            ssl_key => "/etc/pki/tls/private/logstash-forwarder.key"
          }
}
filter {
    	if [type] == "attacklog" {
        		grok {
    		patterns_dir => "/opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-patterns-core-0.1.10/patterns"
          		match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{IP:IPAddress}/%{IP:SourceIP} %{PROG:Program}: %{CISCO_REASON:AttackType}%{QS:AttackSize} %{GREEDYDATA:Message}" }
        		}
                    date {
                            match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
                    }
    	}	
}
output {
      elasticsearch { host => localhost }
      stdout { codec => rubydebug }
}

```

Stdout log:

```
{
       "message" => "Jun 18 14:50:35 0.0.0.0/0.0.0.0 pfsp: anomaly ICMP_Misuse id 123 status ongoing severity 5 classification high impact 13.90 Mbps/18.19 Kpps src 0.0.0.0/0 All dst 0.0.0.0/0 abc start 2015-06-17 07:10:07 +0000 duration 179 percent 181.870000 rate 10000 rateUnit pps protocol icmp flags nil url https://abc/page?id=alert_view&alert_id=123, (managed object NXG_INFRA), (parent managed object nil)",
      "@version" => "1",
    "@timestamp" => "2015-06-18T10:32:07.385Z",
          "type" => "attacklog",
          "file" => "/var/log/attack.log",
          "host" => "syslogserver",
        "offset" => "7210",
          "tags" => [
        [0] "_grokparsefailure"
    ]
}

```

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![Penny\_Lee](https://avatars.discourse-cdn.com/v4/letter/p/df788c/32.png) [@Penny\_Lee](https://discuss.elastic.co/u/Penny_Lee)\
**Post date:** [June 24, 2015, 9:49am UTC](https://discuss.elastic.co/t/logstash-filter-plugin-patterns-core/23900/2 "2015-06-24T09:49:30Z")

</div>

Its fixed. Formerly, logstash have installed the plugin logstash-patterns-core.  
It should touch the file in the /opt/logstash/patterns, and you can define the your grok pattern to use in the filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:36am UTC](https://discuss.elastic.co/t/logstash-filter-plugin-patterns-core/23900/3 "2017-07-06T05:36:38Z")

</div>


